{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T02:23:36.022","vulnerabilities":[{"cve":{"id":"CVE-2024-50365","sourceIdentifier":"prodsec@nozominetworks.com","published":"2024-11-26T11:22:03.430","lastModified":"2026-06-17T08:04:18.903","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A CWE-78 \"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the \"lan_apply\" API which are not properly sanitized before being concatenated to OS level commands."},{"lang":"es","value":"Se descubrió una vulnerabilidad CWE-78 \"Neutralización incorrecta de elementos especiales utilizados en un comando del SO ('Inyección de comando del SO')\" que afectaba a los siguientes dispositivos fabricados por Advantech: EKI-6333AC-2G (&lt;= 1.6.3), EKI-6333AC-2GD (&lt;= v1.6.3) y EKI-6333AC-1GPO (&lt;= v1.2.1). La fuente de la vulnerabilidad se basa en múltiples parámetros pertenecientes a la API \"lan_apply\" que no se desinfectan correctamente antes de concatenarse con comandos de nivel del SO."}],"affected":[{"source":"prodsec@nozominetworks.com","affectedData":[{"vendor":"Advantech","product":"EKI-6333AC-2G","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"<= 1.6.3","versionType":"semver","status":"affected"}]},{"vendor":"Advantech","product":"EKI-6333AC-2GD","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"<= 1.6.3","versionType":"semver","status":"affected"}]},{"vendor":"Advantech","product":"EKI-6333AC-1GPO","defaultStatus":"unaffected","versions":[{"version":"0","lessThanOrEqual":"<= 1.2.1","versionType":"semver","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"advantech","product":"eki-6333ac-2g_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:advantech:eki-6333ac-2g_firmware:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"1.6.3","versionType":"custom","status":"affected"}]},{"vendor":"advantech","product":"eki-6333ac-2gd_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:advantech:eki-6333ac-2gd_firmware:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"1.6.3","versionType":"custom","status":"affected"}]},{"vendor":"advantech","product":"eki-6333ac-1gpo_firmware","defaultStatus":"unknown","cpes":["cpe:2.3:o:advantech:eki-6333ac-1gpo_firmware:*:*:*:*:*:*:*:*"],"versions":[{"version":"0","lessThanOrEqual":"1.2.1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"prodsec@nozominetworks.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","baseScore":7.2,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-26T14:46:14.274310Z","id":"CVE-2024-50365","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"prodsec@nozominetworks.com","type":"Secondary","description":[{"lang":"en","value":"CWE-78"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:advantech:eki-6333ac-2g_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.6.5","matchCriteriaId":"B5E027C8-2521-45FC-BABB-4A6E3341F883"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:advantech:eki-6333ac-2g:-:*:*:*:*:*:*:*","matchCriteriaId":"B3B63DF4-0184-4108-B48B-D31179104701"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:advantech:eki-6333ac-2gd_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.6.5","matchCriteriaId":"447F8AEB-2C7C-411A-893C-11C2F7588C82"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:advantech:eki-6333ac-2gd:-:*:*:*:*:*:*:*","matchCriteriaId":"02F70DBA-2D4C-4407-885D-71887A1A7979"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:advantech:eki-6333ac-1gpo_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"1.2.2","matchCriteriaId":"828B9D05-0064-4690-A624-D3BF659BD316"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:advantech:eki-6333ac-1gpo:-:*:*:*:*:*:*:*","matchCriteriaId":"D2A73A2B-9FD5-4971-8FFF-1BA14BCCB37B"}]}]}],"references":[{"url":"https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-50365","source":"prodsec@nozominetworks.com","tags":["Third Party Advisory"]}]}}]}